(Enter summary)
Abstract: We present a polynomial-time algorithm that provably recovers the signer's secret DSA key when a few bits of the random nonces k (used at each signature generation) are known for a number of DSA signatures at most linear in log q (q denoting as usual the small prime of DSA), under a reasonable assumption on the hash function used in DSA. The number of required bits is about log 1/2 q, and can be further decreased to 2 if one assumes access to ideal lattice basis reduction, namely an oracle for... (Update)
Cited by: More
On the Provable Security of an Efficient RSA-Based.. - Steinfeld, Pieprzyk.. (2006)
(Correct)
One-Time HNP or Attacks on a Flawed El Gamal Revisited - Rosa (2005)
(Correct)
Experimenting with Faults, Lattices and the DSA - Naccache, Nguyen, Tunstall.. (2005)
(Correct)
Similar documents (at the sentence level):
48.4%: The Insecurity of the Digital Signature Algorithm with.. - Nguyen, Shparlinski (2000)
(Correct)
22.5%: The Insecurity of the Elliptic Curve Digital Signature.. - Nguyen, Shparlinski (2000)
(Correct)
Active bibliography (related documents): More All
0.6: Lattice Reduction in Cryptology: An Update - Nguyen, Stern (2000)
(Correct)
0.4: Generalized Compact Knapsacks, Cyclic Lattices, and Efficient.. - Micciancio (2004)
(Correct)
0.4: The Two Faces of Lattices in Cryptology - Nguyen, Stern (2001)
(Correct)
Similar documents based on text: More All
0.6: Cryptanalysis of MQV with partially known nonces - Leadbitter, Smart (2002)
(Correct)
0.5: Hidden Number Problem in Small Subgroups - Shparlinski, Winterhof (2003)
(Correct)
0.5: Distribution Of Modular Sums And The Security Of The Server .. - Nguyen, Shparlinski (2000)
(Correct)
Related documents from co-citation: More All
16: Hardness of Computing the Most Significant Bits of Secret Keys in Diffie-Hellman.. (context) - Boneh, Venkatesan
14: The insecurity of the elliptic curve Digital Signature Algorithm with partially ..
- Nguyen, Shparlinski - 2000
11: Lattice attacks on digital signature schemes (context) - Howgrave-Graham, Smart - 2001
BibTeX entry: (Update)
P. Nguyen and I. E. Shparlinski, `The insecurity of the Digital Signature Algorithm with partially known nonces', Preprint , 2000, 1--18. http://citeseer.ist.psu.edu/article/nguyen00insecurity.html More
@misc{ nguyen00insecurity,
author = "P. Nguyen and I. Shparlinski",
title = "The insecurity of the Digital Signature Algorithm with partially known
nonces",
note = "Preprint , 2000, 1--18.",
year = "2000",
url = "citeseer.ist.psu.edu/article/nguyen00insecurity.html" }
Citations (may not include all citations):
1065
Handbook of Applied Cryptography (context) - Menezes, Van Oorschot et al. - 1997
659
Random oracles are practical: a paradigm for designing e#cie..
- Bellare, Rogaway - 1993
309
Random number generation and quasi--Monte Carlo methods (context) - Niederreiter - 1992
239
Cryptography: Theory and Practice (context) - Stinson - 1995
186
A public key cryptosystem and a signature scheme based on di.. (context) - Gamal - 1985
115
Uniform distribution of sequences (context) - Kuipers, Niederreiter - 1974
88
cient signature generation by smart cards (context) - Schnorr - 1991
66
On Lovasz lattice reduction and the nearest lattice point pr.. (context) - Babai - 1986
60
Lattice basis reduction: improved practical algorithms and s..
- Schnorr, Euchner - 1994
55
Hardness of computing the most significant bits of secret ke.. (context) - Boneh, Venkatesan - 1996
27
Character sums with exponential functions and their applicat.. (context) - Konyagin, Shparlinski - 1999
20
Factoring polynomials with rational coe#cients (context) - Lenstra, Lenstra et al. - 1982
19
Lattice reduction in cryptology: An update
- Nguyen, Stern - 2000
19
FIPS Publication 186: Digital Signature Standard (context) - of, Technology - 1994
18
Hidden collisions on DSS
- Vaudenay - 1996
17
discrepancies and applications (context) - Drmota, Tichy - 1997
14
Security of the most significant bits of the Shamir message .. (context) - Vasco, Shparlinski - 2000
13
A hierarchy of polynomial lattice basis reduction algorithms (context) - Schnorr - 1987
13
Design validations for discrete logarithm based signature sc..
- Brickell, Pointcheval et al. - 2000
11
Lattice attacks on digital signature schemes (context) - Howgrave-Graham, Smart - 1999
11
Pseudo-random (context) - Bellare, Goldwasser et al. - 1997
11
The dark side of the hidden number problem: Lattice attacks .. (context) - Nguyen - 2000
5
Number Theory C++ Library (context) - Shoup
4
Exponential sums and goppa codes (context) - Moreno, Moreno - 1991
3
Private communication (context) - Bleichenbacher - 1999
3
the uniformity of distribution of the El Gamal signature
- Shparlinski - 2000
3
Breaking knapsack cryptosystems by max-norm enumeration (context) - Ritter - 1996
The graph only includes citing articles where the year of publication is known.
Documents on the same site (http://www.comp.mq.edu.au/~igor/Publ.html): More
A Lower Bound for Primality - Allender, Saks, Shparlinski (1999)
(Correct)
Finding Points on Curves over Finite Fields - Gathen, Shparlinski, Sinclair (1996)
(Correct)
A Public Key Cryptosystem Based On Sparse Polynomials - Grant, Lieman, Shparlinski (1998)
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC